@doist/reactist
Open source React components by Doist
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): Named maintainers are known Doist org members; consistent with org-managed package published via GitHub Actions CI. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): patch-package postinstall is a standard dependency-patching pattern; stable for this package. | ai | |
| phantom-deps | phantom-dep:patch-package | AI (phantom-deps): patch-package is invoked via postinstall script, not imported; phantom-dep is a false positive here. | ai | |
| phantom-deps | phantom-dep:react-markdown | AI (phantom-deps): react-markdown is a runtime dep used in components; phantom-dep heuristic misfires on this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established Doist OSS library; README signals are false positives for this well-known package. | ai |
Versions (showing 12 of 12)
| Version | Deps | Published |
|---|---|---|
| 31.3.0 | 8 / 74 | |
| 31.0.0 | 8 / 102 | |
| 30.1.4 | 8 / 105 | |
| 30.1.2 | 8 / 105 | |
| 30.1.1 | 8 / 105 | |
| 30.0.1 | 8 / 100 | |
| 29.1.2 | 8 / 99 | |
| 29.1.1 | 7 / 93 | |
| 29.1.0 | 7 / 93 | |
| 29.0.0 | 7 / 93 | |
| 28.7.4 | 8 / 91 | |
| 28.7.3 | 8 / 89 |
v31.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v31.0.0
2 findingsScript: patch-package
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v30.1.2
2 findingsScript: patch-package
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v30.1.1
2 findingsScript: patch-package
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v30.0.1
2 findingsScript: patch-package
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v29.1.2
2 findingsScript: patch-package
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v29.1.1
2 findingsScript: patch-package
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v29.1.0
2 findingsScript: patch-package
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v29.0.0
2 findingsScript: patch-package
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v28.7.4
2 findingsScript: patch-package
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v28.7.3
2 findingsScript: patch-package
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.